Files
bambuddy/deploy/bambuddy.service
maziggy fb1e9a917e fix(install): use ProtectHome=read-only for /home-rooted installs (#1685)
bambuddy.service shipped with ProtectHome=true, which makes /home/* invisible
  to the service namespace. Installing into /home/bambuddy/ (instead of the
  default /opt/bambuddy/) made ExecStart=/home/bambuddy/venv/bin/uvicorn fail
  with status=203/EXEC because systemd couldn't resolve the binary path.
  ReadWritePaths=$INSTALL_PATH does not reliably re-expose /home/* subpaths for
  exec resolution.

  install/install.sh now detects /home/* INSTALL_PATH and emits ProtectHome=read-only;
  default /opt/bambuddy installs keep ProtectHome=true. The manual deploy template
  defaults to read-only with a comment on when to tighten it.

  read-only keeps /home immutable to the service - no security regression, since
  ReadWritePaths still gates writes to the install/data/log dirs only.
2026-06-09 07:31:23 +02:00

65 lines
1.8 KiB
Desktop File

# BamBuddy Systemd Service Template
#
# INSTALLATION:
# 1. Copy this file to /etc/systemd/system/bambuddy.service
# 2. Replace placeholders:
# - INSTALL_PATH: Where BamBuddy is installed (e.g., /opt/bambuddy)
# - SERVICE_USER: User to run as (e.g., bambuddy)
# - DATA_DIR: Data directory (e.g., /opt/bambuddy/data)
# - LOG_DIR: Log directory (e.g., /opt/bambuddy/logs)
# 3. Run: sudo systemctl daemon-reload
# 4. Run: sudo systemctl enable bambuddy
# 5. Run: sudo systemctl start bambuddy
#
# Or use the install script: ./install/install.sh
#
[Unit]
Description=BamBuddy - Bambu Lab Print Management
Documentation=https://github.com/maziggy/bambuddy
After=network.target
[Service]
Type=simple
User=SERVICE_USER
Group=SERVICE_USER
WorkingDirectory=INSTALL_PATH
# Environment file (optional - created by install script)
EnvironmentFile=-INSTALL_PATH/.env
# Use virtual environment
Environment="PATH=INSTALL_PATH/venv/bin:/usr/local/bin:/usr/bin:/bin"
# Server configuration
ExecStart=INSTALL_PATH/venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000}
# Restart policy
Restart=on-failure
RestartSec=5
# Graceful shutdown
TimeoutStopSec=10
# Kill zombie ffmpeg processes (timelapse processing)
ExecStartPre=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
ExecStopPost=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
# Logging
StandardOutput=journal
StandardError=journal
SyslogIdentifier=bambuddy
# Security hardening
NoNewPrivileges=true
PrivateTmp=true
ProtectSystem=strict
# ProtectHome=true hides /home/* and breaks ExecStart when INSTALL_PATH is
# under /home (issue #1685). Default is the safer read-only; flip to true if
# your INSTALL_PATH is outside /home (e.g. /opt/bambuddy).
ProtectHome=read-only
ReadWritePaths=DATA_DIR LOG_DIR INSTALL_PATH
[Install]
WantedBy=multi-user.target